CVE-2025-12696
HelloLeads CRM Form Shortcode <= 1.0 - Unauthenticated Settings Reset
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
10th
The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them
| Vendor | unknown |
| Product | helloleads crm form shortcode |
| Published | Dec 14, 2025 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown helloleads crm form shortcode
Be the first to know when new medium vulnerabilities affecting unknown helloleads crm form shortcode are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / HelloLeads CRM Form Shortcode
0 โค 1.0
References
Credits
Khaled Alenazi (Nxploited) WPScan